Skip to content
Legal

Privacy & Cookie Policy

How Prism Integrated Security Solutions Ltd collects, uses, retains and protects your personal data — and the rights you have over it.

Last updated: 23 August 2026

This notice explains how Prism Integrated Security Solutions Ltd (“Prism”, “we”, “us”) collects, uses, stores and shares personal data, and the rights available to you. It is provided under Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our use of cookies is additionally governed by the Privacy and Electronic Communications Regulations 2003 (PECR).

It applies to:

  • visitors to this website, including anyone using our online system builders or booking a survey
  • people who contact us by telephone, email or through our enquiry forms
  • customers who engage us to install, maintain or monitor security or MediCare systems, and users of our customer portal
  • keyholders and contacts registered on alarm monitoring accounts

1. Who we are

The data controller — the organisation responsible for deciding how your personal data is used — is Prism Integrated Security Solutions Ltd, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.

We are registered with the Information Commissioner’s Office (ICO) under reference ZC183779. You can verify registered data controllers on the ICO register.

For anything in this notice, or to exercise any of your rights, contact our data protection contact at dpo@prismintegratedsecurity.solutions, call 0330 236 8191, or write to the registered office above. You can also use the form on our contact page.

2. The personal data we collect

We collect only the data needed for a specific, stated purpose. What we hold depends on your relationship with us.

Enquiries and contact forms

  • Identity and contact data — your name, email address and phone number
  • Company name and postcode, where you provide them
  • The content of your message, and your marketing preference (an unticked opt-in box)

Online system builders

If you design a system with our alarm or MediCare builder, we collect your contact details, the installation address, and the property details you enter — floors, rooms, doors and windows — because they are the design. For business customers we also look up and store your company’s registered name, number and registered office from the Companies House public register, so your quotation names the right legal entity.

Health information (special category data)

The MediCare builder includes a free-text notes field where you may choose to tell us about health considerations — for example, that the person the system is for is at risk of falls. This is special category data under Article 9 UK GDPR. We process it only with your explicit consent, which you give by choosing to write it, and we use it solely to design and deliver a suitable system. Share only what you are comfortable sharing — the builder works without it — and you can ask us to delete these notes at any time by contacting dpo@prismintegratedsecurity.solutions.

Survey bookings

When you book a survey we collect your name, contact details, the site address and your chosen appointment slot. If you give us a mobile number we send booking confirmations and appointment reminders by text message. These are service messages, not marketing.

Customers

  • Contract and service data — quotations, contracts, invoices, installed systems and equipment, certificates, maintenance history and engineer visit notes
  • Site data — installation addresses and, for monitored systems, access details, zone descriptions and response procedures
  • Keyholder data — names, phone numbers and call priorities for the keyholders you nominate on a monitoring account
  • Payment data — we invoice for payment by bank transfer, so we see the payer name and reference on incoming payments. We do not collect or store card numbers.

If you nominate keyholders, you must make sure those people know their details will be shared with our monitoring partner for alarm response. Point them to this notice.

Customer portal accounts

Portal accounts hold your sign-in email address, your sign-in history, and the documents we have issued to you — quotations, invoices and certificates.

Signing your contract electronically

When you sign a Job Specification from the link we email you, we record your name, the capacity you sign in (for example home owner or director), your drawn signature, the date and time, and the technical details of the signing session — the IP address the request came from, your browser’s identifying string, and a one-off signing reference generated in your browser. These form part of the contract record: they are the evidence that the signature was given, our lawful basis for them is the contract itself, and we keep them for as long as we keep the signed contract.

Technical data

Our hosting infrastructure records standard server logs (IP address, browser type, pages requested) which we use for security and fault diagnosis. Our website analytics are aggregate and cookie-free — see the cookies section below.

3. Why we use it, and our lawful bases

Under Article 6 UK GDPR we must have a lawful basis for every use of personal data. These are ours:

What we doLawful basis
Respond to enquiries, prepare quotations and arrange surveysLegitimate interests — Article 6(1)(f): responding to people who ask us to
Design, install, commission, maintain and repair your system; run your portal accountContract — Article 6(1)(b)
Share keyholder and site data with our Alarm Receiving Centre for 24/7 monitoringContract — Article 6(1)(b): integral to the monitoring service
Send service messages — booking confirmations, appointment reminders, maintenance reminders, renewal noticesContract and legitimate interests — Articles 6(1)(b) and 6(1)(f)
Process health notes you volunteer in the MediCare builderExplicit consent — Articles 6(1)(a) and 9(2)(a)
Keep accounting, tax and contractual recordsLegal obligation — Article 6(1)(c): Companies Act 2006, HMRC requirements
Email marketing to existing customers about similar servicesLegitimate interests — Article 6(1)(f), with the PECR Regulation 22 soft opt-in; every message includes an opt-out
Email marketing where you ticked the opt-in box on an enquiryConsent — Article 6(1)(a) and PECR Regulation 22
Secure our systems, prevent fraud, and establish or defend legal claimsLegitimate interests — Article 6(1)(f)
Respond to legal, regulatory or law-enforcement requestsLegal obligation — Article 6(1)(c)

Where we rely on legitimate interests we have balanced our interests against your rights and freedoms. You can object to any processing based on legitimate interests — see your rights below. You can stop marketing at any time using the unsubscribe link in any marketing email or by contacting us; opting out never affects service messages about work you have asked us to do.

4. Who we share it with

We do not sell, rent or trade personal data — to anyone, ever. We share it only where necessary, under written contracts that meet Article 28 UK GDPR.

Alarm monitoring — EMCS

Monitored systems are connected to EMCS (East Midlands Central Station Limited), the UK’s largest independent Alarm Receiving Centre, NSI Gold certified. EMCS processes keyholder and alarm event data as our data processor, under a written data processing agreement, only on our instruction and only to provide monitoring and response.

Service providers

  • Supabase — our database, customer sign-in and document storage, hosted on AWS in London (UK)
  • Vercel — website hosting and cookie-free, aggregate analytics
  • Resend — delivery of the emails we send you
  • Twilio — delivery of booking confirmation and reminder text messages

Others

  • Vetted subcontracted engineers, who receive only the minimum needed for a specific job — typically the site address and access arrangements — under written confidentiality agreements
  • Professional advisers — accountants, solicitors and insurers — where necessary, bound by professional confidentiality
  • Police, courts, regulators and other public authorities, where the law requires it; we will tell you unless we are legally prevented from doing so

5. International transfers

Your data is stored in the United Kingdom — our database, documents and sign-in records live in a London data centre. Some of our service providers are US companies, so limited data (for example, an email address on an outgoing email, or a phone number on a text message) may be processed outside the UK. Where that happens we rely on the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge) or the ICO’s International Data Transfer Agreement, as Chapter V UK GDPR requires.

6. How long we keep it

CategoryRetention periodWhy
Enquiry and builder data where no contract follows3 years from last contactLegitimate interests — limitation periods for civil claims
Customer contract records — identity, contact, service history, certificates, invoices7 years from contract endLegal obligation — Companies Act 2006, HMRC requirements
Alarm monitoring and keyholder dataDuration of the monitoring contract + 3 yearsContract performance; post-contract queries
Health notes volunteered in the MediCare builderDeleted on request; otherwise retained with the related enquiry or contract recordExplicit consent — withdrawable at any time
Marketing consent recordsUntil consent is withdrawn + 3 yearsLegal obligation — evidence of valid consent under PECR
Complaints, disputes and legal correspondence6 years from resolutionLimitation Act 1980
CCTV footage at our own premises31 daysLegitimate interests — ICO surveillance guidance

When a retention period ends, data is securely deleted or anonymised. We may keep data longer where a court order, live legal proceedings or a specific regulatory obligation requires it, and will tell you where that applies.

7. How we protect it

  • Encryption in transit for every connection to the website and portal
  • Row-level access controls in the database — a portal account can read its own records and nothing else
  • Least-privilege staff access, with an append-only audit log recording who changed what
  • Documents stored in a private bucket, never on public URLs

8. Automated processing

Our online builders generate a system specification and draft quotation automatically from your answers. A person reviews every quotation before it is sent, and no decision producing legal or similarly significant effects is made about you by automated means alone.

9. Your rights

Under UK GDPR you have the right to:

  • Access (Article 15) — request a copy of the personal data we hold about you (a Subject Access Request)
  • Rectification (Article 16) — have inaccurate or incomplete data corrected
  • Erasure (Article 17) — have data deleted where there is no compelling reason to keep it
  • Restriction (Article 18) — limit how we use your data, for example while you contest its accuracy
  • Portability (Article 20) — receive data you gave us in a structured, machine-readable format, where processing is based on consent or contract
  • Objection (Article 21) — object to processing based on legitimate interests, and to direct marketing, which we must stop immediately
  • Freedom from solely automated decisions (Article 22) — as described above, we do not make any
  • Withdraw consent at any time, where processing relies on it — including health notes and marketing. Withdrawal does not affect processing already carried out.

To exercise any right, email dpo@prismintegratedsecurity.solutions or use the contact page. We respond within one calendar month and there is no fee, though we may need to verify your identity first. Some rights are subject to legal exemptions — where one applies, we will explain it.

You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would welcome the chance to resolve your concern first.

10. Cookies

This website sets strictly necessary cookies only — the session cookies that keep you signed in to the customer portal. Under PECR these need no consent, which is why you see no cookie banner.

We do not set analytics, advertising or social media cookies. Specifically:

  • our visitor analytics (Vercel Web Analytics) are cookie-free and aggregate — no identifier is stored on your device and no profile of you is built
  • there are no Google Analytics, Meta, LinkedIn or TikTok tags on this site
  • no third party sets cookies through this site for its own purposes

You can block or delete cookies in your browser settings at any time; blocking the portal session cookie simply means you cannot stay signed in. If we ever introduce cookies that require consent, we will add a consent mechanism and update this policy before they are set.

11. CCTV installed at your property

Where we install a CCTV system at your property, you are the data controller for the footage it captures — not Prism — and you have your own obligations under UK GDPR: display clear signage, limit retention (we recommend 31 days by default), store footage securely, and respond within one month to access requests from people who appear in it. The ICO’s video surveillance guidance explains these duties.

During installation, commissioning and maintenance our engineers may view live or recorded footage solely for testing and diagnosis. We do not copy, retain or store footage from customer systems, and any remote access for fault diagnosis is logged and limited to the minimum necessary. Ajax systems we install use end-to-end encryption; alarm verification images sent to EMCS are processed only to verify activations, and data in the Ajax Cloud is governed by Ajax’s own privacy policy.

12. Children

Our website and services are not directed at children under 13 and we do not knowingly collect their data. MediCare systems are arranged by adults on behalf of the person they care for. If you believe a child has given us personal data, contact dpo@prismintegratedsecurity.solutions and we will delete it.

13. Changes to this notice

We review this notice regularly and update it when our practices, the law or ICO guidance change. Material changes affecting existing customers will be emailed at least 14 days before they take effect. The date at the top is the date of the current version.